nerdexam
CompTIA

CAS-003 · Question #720

An information security officer reviews a report and notices a steady increase in outbound network traffic over the past ten months. There is no clear explanation for the increase. The security…

The correct answer is C. CASB. A Cloud Access Security Broker (CASB) provides visibility and policy enforcement over cloud service usage, directly addressing the shadow IT risk of unsanctioned cloud storage.

Enterprise Security Operations

Question

An information security officer reviews a report and notices a steady increase in outbound network traffic over the past ten months. There is no clear explanation for the increase. The security officer interviews several business units and discovers an unsanctioned cloud storage provider was used to share marketing materials with potential customers. Which of the following services would be BEST for the security officer to recommend to the company?

Options

  • ANIDS
  • BHIPS
  • CCASB
  • DSFTP

How the community answered

(40 responses)
  • A
    5% (2)
  • C
    93% (37)
  • D
    3% (1)

Why each option

A Cloud Access Security Broker (CASB) provides visibility and policy enforcement over cloud service usage, directly addressing the shadow IT risk of unsanctioned cloud storage.

ANIDS

A Network Intrusion Detection System (NIDS) monitors traffic for known attack signatures but does not provide governance or visibility specifically over which cloud services employees are accessing.

BHIPS

A Host Intrusion Prevention System (HIPS) monitors activity on individual endpoints but cannot identify or enforce policies against unsanctioned cloud service usage across the organization.

CCASBCorrect

A CASB acts as an intermediary between users and cloud service providers, giving the security team full visibility into all cloud services in use - including unsanctioned ones discovered through shadow IT. It can enforce policies to block, monitor, or control unauthorized cloud storage providers, preventing data leakage and compliance violations caused by employees using unapproved services.

DSFTP

SFTP is a secure file transfer protocol that could serve as a sanctioned alternative, but it does not detect, govern, or restrict the use of unauthorized third-party cloud storage services.

Concept tested: Cloud Access Security Broker (CASB) for shadow IT control

Source: https://learn.microsoft.com/en-us/defender-cloud-apps/what-is-defender-for-cloud-apps

Topics

#CASB#shadow IT#cloud storage#DLP

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice